Notes for owners · Industry playbooks
How ISO consultants keep surveillance and renewal revenue
Certification is not the end of the engagement. The surveillance and recertification work is already yours, and it leaks because nobody wrote the dates down.
The GullySales team · Updated 3 Oct 2026 · 7 min read
On this page
The surveillance and recertification work in your practice is already won. It leaks because nobody wrote the dates down, the client heard from the certification body first, and by then someone cheaper had offered to handle it. Build a single list of every certificate you have ever helped obtain, with its dates and the body that issued it, and put a reminder well ahead of each audit. That list is usually worth more than the next quarter of new enquiries.
The work you already sold and never collected
A consultant finishes a certification, invoices, and moves on to the next enquiry. The client's management system then sits untouched until a letter arrives from the certification body about the next audit. The client panics, searches, and engages whoever answers.
Nothing about that is a marketing failure. It is a record-keeping failure.
Certificates carry a cycle of surveillance audits and a recertification at the end of it, and the exact pattern is set by the certification body and the standard, and it changes. So do not work from a rule of thumb. Read the dates on the client's own certificate and diarise those.
Build the list before you build anything else
One sheet. One row per certificate. It takes an afternoon and most practices have never done it.
| Column | Why it is there |
|---|---|
| Client and site | Multi-site clients need a row each, because audits are scheduled separately |
| Standard | The second standard conversation starts here |
| Certification body | Who will write to the client, and when |
| Certificate issue and expiry dates | The arithmetic that drives every reminder |
| Next audit date as stated | The only date that matters |
| Who signed and who runs the system now | The person who left took your relationship with them |
| Last contact | Shows how cold the relationship has gone |
The last two columns are the ones consultants skip and regret. A quality manager moves on, the new one has never heard of you, and the certification body's email goes to a plant head who forwards it to a search engine.
Reach the client before the body does
The reminder from the certification body is a bill. A note from you, earlier, is help.
Write to the person running the system, name the audit date on their certificate, and list what has to happen before it: internal audits completed, a management review held, corrective actions from the last audit closed, records current. Offer to walk through where they stand. That note converts because it arrives when the client has not yet started worrying, and because nobody else sent it.
For example, a consultant in Peenya, Bengaluru with sixty past clients in auto components and fabrication. The figures are illustrative. Forty of those certificates are still live and twenty-eight have had no contact since the certification audit. A letter and a call to those twenty-eight, each naming their own audit date, is a day of work with no advertising spend behind it.
One client, more than one standard
A company that has been through a quality system audit once is far easier to take through a second standard than any stranger is to take through a first. The team knows what documentation means, the management review habit exists, and the fear has gone.
Ask what their customers are now demanding. An exporter being asked about environmental performance, a food business whose buyer wants a safety standard, an IT services firm whose client has sent a security questionnaire, and a factory adding a second unit, are four live engagements inside a client list you already have. None of them will raise it with you, because they do not know you do it.
Do this as a short review with the client rather than as an offer. Walk the site, look at what their customers are asking for in writing, and come back with what fits. Honest answers include telling them a standard is not worth it for their size.
Rebuilding a list you have already lost
Most practices cannot reconstruct their own history. Start anyway.
- Go through old invoices and email folders and pull out every client name and the standard involved.
- Ask your contacts at certification bodies and auditors which of your past clients are still certified. Many will say.
- Check public registers of certified companies, which bodies and accreditation bodies commonly publish.
- Ring the ones you cannot place. A call that opens with the year you worked together and the standard is welcome, not awkward.
- Where a certificate has already lapsed, say so plainly and ask what happened. Half of them lapsed because nobody reminded anybody.
The thing not worth doing: advertising for ISO enquiries while this list sits unbuilt. Paid enquiries in this category are price shoppers comparing four quotes, and you will win some at a thin fee. The list costs nothing and the client already trusts you.
What to do next
Open a spreadsheet and put in the ten clients whose certificates you can remember without looking anything up. Add the audit dates from their certificates. Ring the three whose next date is closest. That is the whole method, and the only hard part is the afternoon it takes to do the other fifty. If you want the list built properly and the outreach written, that is what we scope in the free audit.